Back to Blog
CVE-2026-8233: Dotouch 4G/5G Core — Remote Session Hijack & DoS (July 2026)
vulnerabilities

CVE-2026-8233: Dotouch 4G/5G Core — Remote Session Hijack & DoS (July 2026)

breachwire TeamAug 1, 20262 min read

CVE-2026-8233 — Dotouch 4G/5G Core

CVE-2026-8233 is a high-severity vulnerability affecting both open-source and commercial 4G/5G core network components, including Dotouch and at least one major unnamed carrier. It enables remote attackers to hijack user sessions and trigger denial-of-service (DoS) conditions by exploiting protocol trust flaws in GTP-C and PFCP. No evidence of active exploitation has been reported, but the attack surface is significant given the global deployment of vulnerable core network stacks.

Attack Vector

Attackers—either remote or operating compromised/malicious user equipment—leverage implicit trust weaknesses in GTP-C (GPRS Tunneling Protocol Control) and PFCP (Packet Forwarding Control Protocol). By crafting malicious protocol messages, adversaries can crash core network components (DoS) or hijack user sessions, redirecting uplink traffic to attacker-controlled infrastructure. No authentication or privileged access is required beyond network connectivity, making exploitation feasible from both internal and external threat actors.

Who Is at Risk

Confirmed affected: Dotouch 5G core network deployments (patch available) and one major unnamed commercial 5G carrier (remediation pending). All organizations running vulnerable LTE/4G/5G core network components—especially those using open-source stacks or custom protocol implementations—are at risk. Global mobile operators and private 5G deployments should assume exposure unless validated otherwise.

Patch & Mitigate

  • Patch: Apply the latest Dotouch core network patch immediately. Other vendors/carriers should follow vendor-specific advisories as soon as available.
  • Workaround: Restrict untrusted or unauthenticated network access to GTP-C and PFCP interfaces. Implement strict network segmentation for core components.
  • Detect: Monitor for anomalous GTP-C/PFCP traffic, unexpected session establishment/teardown, and unexplained DoS events in core network logs.

MITRE ATT&CK

  • TA0005 — Defense Evasion: Attackers exploit protocol trust to bypass standard authentication and authorization checks.
  • TA0001 — Initial Access: Malicious user equipment or remote actors gain access to core network protocols to initiate attacks.

Source: https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: